Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly prior to v2019.11.04.00.
[
{
"id": "CVE-2019-11934-15cae1b6",
"signature_type": "Line",
"digest": {
"line_hashes": [
"227842235891407263626649147242593756560",
"92515533098277077246808838987096168480",
"41501300739345054074027572364971077221"
],
"threshold": 0.9
},
"target": {
"file": "folly/io/async/test/AsyncSSLSocketTest.cpp"
},
"source": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2019-11934-758d6fc6",
"signature_type": "Function",
"digest": {
"length": 2886.0,
"function_hash": "152049047512235869806428153343173593161"
},
"target": {
"function": "AsyncSSLSocket::performWrite",
"file": "folly/io/async/AsyncSSLSocket.cpp"
},
"source": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2019-11934-7b897f9f",
"signature_type": "Line",
"digest": {
"line_hashes": [
"91174101857615857246751717836782017619",
"224397719918820131799092403530216005212",
"110074145152088808578488804447035882284",
"205537247213205996188687327878743244821"
],
"threshold": 0.9
},
"target": {
"file": "folly/io/async/test/AsyncSSLSocketTest.h"
},
"source": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2019-11934-da104a4d",
"signature_type": "Function",
"digest": {
"length": 916.0,
"function_hash": "226764733386146705970750092482506010766"
},
"target": {
"function": "AsyncSSLSocket::interpretSSLError",
"file": "folly/io/async/AsyncSSLSocket.cpp"
},
"source": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2019-11934-da75beb9",
"signature_type": "Line",
"digest": {
"line_hashes": [
"75437057547293670865545316756462918993",
"248490720566392302503301509476307803515",
"225147749680642770137217126037952714602",
"81768500371893478651694426530049309823",
"241293062028868454232575807199260944807",
"72012039228958005014011165386187543026",
"71947813208397625691021693678466393605",
"289019617435022390838770355908762110945",
"178404125538460680333652335649950667292",
"227353430085061521589903766563349283893",
"201703756875948512759860003072909010326",
"99817092843894329774962665118647550387",
"105472108802852616133169234456880531832"
],
"threshold": 0.9
},
"target": {
"file": "folly/io/async/AsyncSSLSocket.cpp"
},
"source": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee",
"signature_version": "v1",
"deprecated": false
}
]